CVE-2025-15641: Netskope Client Exposed IOCTL with Insufficient Access Controls
Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the customer IOCTL by sending crafted IOCTL requests to the driver. A successful exploit can result in the bypassing of all anti-tampering protections for the NSClient.Affected Product(s) and Version(s) Product Name: Netskope Client Affected Platform: Windows Affected Version: All version below R138
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netskope Clientto a version that resolves this vulnerability.Fixed in R138 and above - Upgrade
Upgrade
Netskope Clientto a version that resolves this vulnerability.Fixed in R135 (135.1.19.2670 and above ) - Upgrade
Upgrade
Netskope Clientto a version that resolves this vulnerability.Fixed in R132 (132.0.27.2671 and above )
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15641?
CVE-2025-15641 has a risk score of 46.
How can I fix CVE-2025-15641?
To mitigate CVE-2025-15641, ensure that the Netskope Client is updated to the latest version provided by Netskope.
Who is affected by CVE-2025-15641?
CVE-2025-15641 affects users of the Netskope Client on Windows systems, particularly those with administrative privileges.
What are the potential impacts of CVE-2025-15641?
A successful exploit of CVE-2025-15641 can allow a malicious insider to tamper with customer IOCTL, potentially bypassing security measures.
When was CVE-2025-15641 published?
CVE-2025-15641 was published on June 17, 2026.